FreeIPA: Difference between revisions
No edit summary |
No edit summary |
||
| Line 1: | Line 1: | ||
== Installation == | == Installation == | ||
Here are my notes as I fumble my way setting up FreeIPA. | |||
=== Docker === | === Docker === | ||
| Line 66: | Line 67: | ||
=== Samba integration === | === Samba integration === | ||
The freeipa-client-samba tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication. | The <code>freeipa-client-samba</code> tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication. | ||
To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed. | To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed. | ||
First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run: | ==== On the FreeIPA server ==== | ||
{{Highlight | First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run:{{Highlight | ||
| code = # ldapmodify <<EOF | | code = # ldapmodify <<EOF | ||
dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com | dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com | ||
| Line 83: | Line 84: | ||
| lang = terminal | | lang = terminal | ||
}} | }} | ||
Install the adtrust components on the FreeIPA server. Install <code>ipa-server-trust-ad</code> and run <code>ipa-adtrust-install --add-sids</code>. Ensure that your hostname is set to the FQDN of the hostname otherwise this process will fail. If you are using an external DNS server, ensure that the additional service records are present. | |||
Once this is done, try changing an account password. You should see the <code>ipaNTHash</code> field get populated. This is important as the samba ipasam module will use this. | |||
'''The following is probably not needed:''' | |||
Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running <code>kinit admin</code>). | Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running <code>kinit admin</code>). | ||
{{Highlight | {{Highlight | ||
| Line 112: | Line 121: | ||
}} | }} | ||
==== On the Samba server ==== | |||
You can either use a specific binding credential that's shared across all your samba servers, or use the machine's cifs service account to authenticate to the LDAP server. | |||
I tried to do the following using the admin account as the bind DN: ('''this is probably a bad idea''') | |||
{{Highlight | |||
| code = [global] | |||
# freeipa configurations | |||
passdb backend = ipasam:ldap://home.steamr.com | |||
ldap admin dn = uid=admin,cn=users,cn=accounts,dc=home,dc=steamr,dc=com | |||
ldapsam:trusted = yes | |||
ldap suffix = cn=accounts,dc=home,dc=steamr,dc=com | |||
ldap user suffix = cn=users,cn=accounts | |||
ldap machine suffix = cn=computers,cn=accounts | |||
ldap group suffix = cn=groups,cn=accounts | |||
ldap passwd sync = only | |||
ldap ssl = no | |||
| lang = text | |||
}} | |||
Run <code>smbpasswd -w password</code> to set your bind credential passwords. | |||
The other way would be to use a service account. The easiest way is to install the <code>freeipa-client-samba</code> package and then run <code>ipa-client-samba</code>. This should automatically set up the cifs service accounts for this particular samba server, get the samba keytab file in /etc/samba/samba.keytab, and then tweak the smb.conf file to use this keytab file. This also doesn't seem to work as samba doesn't start... hmm | |||
Alternatively, you could try setting a keytab file here so that samba uses a service account in the keytab to authenticate. Perhaps something like this, as [https://web.tecnico.ulisboa.pt/~joaomiguelvieira/public/docs/tutorials/configure_samba_to_use_freeipa_authentication.pdf outlined in this document]. | |||
{{Highlight | |||
| code = dedicated keytab file = FILE:/etc/samba/samba.keytab | |||
kerberos method = dedicated keytab | |||
| lang = text | |||
}} | |||
Your samba server should have the ipa-adtrust-install package. If you don't see it, you likely need to enable a dnf module stream. | |||
== Tasks == | |||
=== Join a computer to a FreeIPA === | |||
Use the <code>ipa-client-install</code> command to add a computer to a FreeIPA server. This should also automatically add a computer account, generate a keytab file, and tweak sssd to use FreeIPA as an authentication mechanism. | |||
{{Highlight | |||
| code = # ipa-client-install -U -p admin -w $Password --server ipa.home.steamr.com --domain home.steamr.com --force-join --no-ntp --fixed-primary | |||
| lang = terminal | |||
}} | |||
== Troubleshooting == | == Troubleshooting == | ||
| Line 147: | Line 192: | ||
| lang = text | | lang = text | ||
}} | }} | ||
==== Can't find the ipa-adtrust-install package ==== | |||
The FreeIPA packages are under a different app stream repo. Enable it by running <code>dnf -y module enable idm:DL1</code>. | |||
Revision as of 04:54, 7 March 2022
Installation
Here are my notes as I fumble my way setting up FreeIPA.
Docker
There is an official Docker container that has a complete FreeIPA installation. This container uses systemd to start up FreeIPA along with the other related services such as OpenLDAP, Bind, and Kerberos. See more at: https://github.com/freeipa/freeipa-container
Use the following docker-compose.yml stack to quickly get started with FreeIPA:
version: '3.3'
services:
freeipa:
image: freeipa/freeipa-server:rocky-8
restart: unless-stopped
tty: true
stdin_open: true
hostname: ipa
domainname: home.steamr.com
extra_hosts:
- "ipa.home.steamr.com:10.1.2.12"
environment:
- IPA_SERVER_HOSTNAME=ipa.home.steamr.com
- IPA_SERVER_IP=10.1.2.12
- DNS=10.1.0.8
- TZ=America/Edmonton
command:
- ipa-server-install
- --realm=home.steamr.com
- --domain=home.steamr.com
- --ds-password=xxxxxxxxxx
- --admin-password=xxxxxxxxxx
- --no-host-dns
- --setup-dns
- --auto-forwarders
- --allow-zone-overlap
- --no-dnssec-validation
- --unattended
sysctls:
- net.ipv6.conf.all.disable_ipv6=0
volumes:
- ./data:/data
- ./logs:/var/logs
- /sys/fs/cgroup:/sys/fs/cgroup:ro
tmpfs:
- /run
- /var/cache
- /tmp
cap_add:
- SYS_TIME
ports:
- "10.1.2.12:80:80/tcp"
- "10.1.2.12:443:443/tcp"
# DNS
- "10.1.2.12:53:53/tcp"
- "10.1.2.12:53:53/udp"
# LDAP(S)
- "10.1.2.12:389:389/tcp"
- "10.1.2.12:636:636/tcp"
# Kerberos
- "10.1.2.12:88:88/tcp"
- "10.1.2.12:464:464/tcp"
- "10.1.2.12:88:88/udp"
- "10.1.2.12:464:464/udp"
Samba integration
The freeipa-client-samba tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication.
To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed.
On the FreeIPA server
First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run:
# ldapmodify <<EOF
dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com
changetype: modify
add: ipaUserObjectClasses
ipaUserObjectClasses: sambaSAMAccount
-
add: ipaGroupObjectClasses
ipaGroupObjectClasses: sambaGroupMapping
EOF
Install the adtrust components on the FreeIPA server. Install ipa-server-trust-ad and run ipa-adtrust-install --add-sids. Ensure that your hostname is set to the FQDN of the hostname otherwise this process will fail. If you are using an external DNS server, ensure that the additional service records are present.
Once this is done, try changing an account password. You should see the ipaNTHash field get populated. This is important as the samba ipasam module will use this.
The following is probably not needed:
Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running kinit admin).
ldapadd <<EOF
dn: cn=SambaSid,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
dnatype: sambaSID
dnaprefix: S-1-5-21-2049073866-1371207509-1214748462
dnainterval: 1
dnamagicregen: assign
dnafilter: (|(objectclass=sambasamaccount)(objectclass=sambagroupmapping))
dnascope: dc=home,dc=steamr,dc=com
cn: SambaSid
dnanextvalue: 2
dn: cn=sambaGroupType,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
cn: sambaGroupType
dnatype: sambaGroupType
dnainterval: 1
dnamagicregen: assign
dnafilter: (objectClass=sambagroupmapping)
dnascope: dc=home,dc=steamr,dc=com
dnanextvalue: 2
EOF
On the Samba server
You can either use a specific binding credential that's shared across all your samba servers, or use the machine's cifs service account to authenticate to the LDAP server.
I tried to do the following using the admin account as the bind DN: (this is probably a bad idea)
[global]
# freeipa configurations
passdb backend = ipasam:ldap://home.steamr.com
ldap admin dn = uid=admin,cn=users,cn=accounts,dc=home,dc=steamr,dc=com
ldapsam:trusted = yes
ldap suffix = cn=accounts,dc=home,dc=steamr,dc=com
ldap user suffix = cn=users,cn=accounts
ldap machine suffix = cn=computers,cn=accounts
ldap group suffix = cn=groups,cn=accounts
ldap passwd sync = only
ldap ssl = no
Run smbpasswd -w password to set your bind credential passwords.
The other way would be to use a service account. The easiest way is to install the freeipa-client-samba package and then run ipa-client-samba. This should automatically set up the cifs service accounts for this particular samba server, get the samba keytab file in /etc/samba/samba.keytab, and then tweak the smb.conf file to use this keytab file. This also doesn't seem to work as samba doesn't start... hmm
Alternatively, you could try setting a keytab file here so that samba uses a service account in the keytab to authenticate. Perhaps something like this, as outlined in this document.
dedicated keytab file = FILE:/etc/samba/samba.keytab
kerberos method = dedicated keytab
Your samba server should have the ipa-adtrust-install package. If you don't see it, you likely need to enable a dnf module stream.
Tasks
Join a computer to a FreeIPA
Use the ipa-client-install command to add a computer to a FreeIPA server. This should also automatically add a computer account, generate a keytab file, and tweak sssd to use FreeIPA as an authentication mechanism.
# ipa-client-install -U -p admin -w $Password --server ipa.home.steamr.com --domain home.steamr.com --force-join --no-ntp --fixed-primary
Troubleshooting
Error: did not receive Kerberos credentials
Tools such as 'ipa' uses your session's Kerberos tickets for authentication. If you don't have any tickets or if your tickets expired, you may get an ipa: ERROR: did not receive Kerberos credentials error. Fix this by running:
## Renew/obtain Kerberos tickets for 'admin'
# kinit admin
Password for admin@HOME.STEAMR.COM: ****
Verify if your tickets are available with klist:
# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin@STEAMR.COM
Valid starting Expires Service principal
03/06/22 14:44:35 03/07/22 14:39:47 krbtgt/STEAMR.COM@STEAMR.COM
Container issues
- mounting /var/log causes the install to break. Something about unable to delete a file in /var/log for whatever reason.
- Error with
AssertionError: Another instance named 'HOME-STEAMR-COM' may already exist. I can't figure out what's causing lib389 to think there's another instance. I built a container image on top of this image with the assertion patched out. This seemed to have fixed the issue. FROM freeipa/freeipa-server:rocky-8 RUN sed 's/assert_c(len(insts)/# assert_c(len(insts)/' -i /usr/lib/python3.6/site-packages/lib389/instance/setup.py
Can't find the ipa-adtrust-install package
The FreeIPA packages are under a different app stream repo. Enable it by running dnf -y module enable idm:DL1.